Last Updated: January 15, 2025
GDPR Compliance Overview
THEITBULLS PRIVATE LIMITED is fully committed to complying with the General Data Protection Regulation (GDPR) (EU) 2016/679. We ensure that all personal data processing activities are conducted in accordance with GDPR requirements.
✓ GDPR Compliant ✓ Data Protection ✓ Privacy by Design
Data Protection Principles
We adhere to the following GDPR data protection principles:
- Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and in a transparent manner.
- Purpose Limitation: We collect data for specified, explicit, and legitimate purposes.
- Data Minimization: We collect only the data necessary for the intended purpose.
- Accuracy: We maintain accurate and up-to-date personal data.
- Storage Limitation: We retain data only as long as necessary.
- Integrity and Confidentiality: We ensure appropriate security measures.
- Accountability: We are responsible for demonstrating GDPR compliance.
Data Subject Rights
Under GDPR, data subjects have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing for marketing purposes
- Right to Withdraw Consent: Withdraw consent at any time
Data Processing Agreement (DPA)
We provide a Data Processing Agreement (DPA) that complies with GDPR requirements. The DPA covers:
- Data processing purposes and duration
- Categories of personal data processed
- Data subject rights and obligations
- Technical and organizational security measures
- Sub-processor management
- Data breach notification procedures
Security Measures
We implement the following security measures to protect personal data:
- Encryption: AES-256 encryption at rest, TLS 1.2+ in transit
- Access Controls: Role-based access with multi-factor authentication
- Monitoring: 24/7 security monitoring and logging
- Backups: Encrypted backups with disaster recovery
- Audits: Regular security audits and vulnerability assessments
Data Breach Response
In the event of a data breach, we have established procedures to:
- Detect and investigate the breach promptly
- Notify affected data subjects within 72 hours
- Report to relevant supervisory authorities
- Take corrective actions to prevent recurrence
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Retention periods vary based on the type of data:
- Account Data: Retained until account deletion
- Message History: Retained for up to 30 days
- Logs & Analytics: Anonymized and retained for longer periods
- Support Tickets: Retained for up to 2 years
International Data Transfers
We comply with GDPR requirements for international data transfers. We use:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions for countries with equivalent protection
- Binding Corporate Rules (BCRs) for internal transfers
Data Protection Officer (DPO)
We have appointed a Data Protection Officer who oversees our GDPR compliance:
Contact Us
For any GDPR-related questions or requests, please contact us: